CVE-2026-42018
Received Received - Intake

JFrog Artifactory Anonymous Token Exposure

Vulnerability report for CVE-2026-42018, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: JFrog

Description

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
jfrog artifactory *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

JFrog Artifactory may unintentionally provide an internal anonymous-user token to unauthenticated users even when anonymous access is disabled. This token could allow unauthorized access to sensitive resources.

Impact Analysis

An attacker could exploit this to gain access to sensitive data or resources in Artifactory, potentially leading to data breaches or unauthorized operations.

Compliance Impact

This vulnerability could lead to unauthorized data exposure, violating confidentiality requirements in GDPR and HIPAA, potentially resulting in legal penalties and loss of trust.

Mitigation Strategies

Disable anonymous access in JFrog Artifactory settings to prevent token exposure. Review and restrict access controls for sensitive resources. Monitor logs for unauthorized token requests or access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42018. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart